MURKYTOP is a Windows command-line reconnaissance utility associated with the China-linked espionage actor APT40, also tracked as BRONZE MOHAWK, Leviathan, Temp.Periscope, and related aliases. It is used during post-compromise operations to map victim networks and support lateral movement. Documented functionality includes identifying remote hosts on connected networks, scanning hosts for open ports, enumerating shared resources on remote systems, retrieving information about users on remote hosts, and deleting local files. Its behavior aligns with internal discovery and operator-driven network exploration rather than autonomous propagation. MURKYTOP has been reported as part of a broader APT40 toolset used against government, academic, maritime, defense, transportation, and other strategic sectors, particularly in espionage campaigns aligned with Chinese state interests.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tools Nanhaishu, Orz, SeDll, Cobalt Strike, GreenCrash, AIRBREAK, BlackCoffee, China Chopper, FUSIONBLAZE, HOMEFRY, MURKYTOP, Metasploit / Meterpreter, ScanBox, Derusbi Trojan, Derusbi, Metasploit
10 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
The content repeatedly describes threat actors and malware performing network scanning, port scanning, service enumeration, OS fingerprinting, and identifying open ports/services across victim environments.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
“actors used the following commands… to enumerate user accounts: net user >> %temp%\download; net user /domain >> %temp%\download … APT1 used the commands net localgroup, net user, and net group to find accounts… APT32 enumerated administrative users using the commands net localgroup administrators … OilRig has run net user, net user /domain, net group "domain admins" /domain …”
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware capable of retrieving information about shares on remote hosts.
Backdoor malware capable of deleting local files.
Command-line reconnaissance tool that can also support lateral movement activities.
A backdoor capable of identifying remote hosts on connected networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.